Description
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product installed and can receive UDP packets from that system.
Published: 2026-08-25
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack‑based buffer overflow exists in SKYSEA Client View and SKYMEC IT Manager. The flaw can be triggered when the affected product receives a UDP packet that is crafted to overflow an internal buffer. An attacker who has logged into a Windows system running the vulnerable product can send such a packet to another Windows system that also has the product installed and is listening for UDP traffic. Successful exploitation would allow the attacker to execute arbitrary code on the target system from the compromised source system.

Affected Systems

The vulnerable products are Sky Co., LTD.’s SKYMEC IT Manager and SKYSEA Client View, both of which run on Windows platforms. No specific version information is available in the current data, so all installed instances of these products are considered at risk.

Risk and Exploitability

The CVSS score is 5.8, indicating medium severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting it is not a high‑profile exploit. Exploitation requires an authenticated user on one host to craft and send the malicious UDP payload to a peer host, which must also host the vulnerable product and accept UDP traffic. While the attack surface is limited to networks where both systems can communicate, the potential impact of arbitrary code execution across systems warrants timely mitigation.

Generated by OpenCVE AI on August 25, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to the latest release of SKYMEC IT Manager and SKYSEA Client View.
  • Configure the local firewall to block inbound UDP traffic on the port used by the product or disable the UDP listening feature if it is not required.
  • Restrict local login privileges on the systems running the vulnerable software and monitor for anomalous UDP activity between hosts.

Generated by OpenCVE AI on August 25, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Stack‑Based Buffer Overflow in SKYSEA Client View and SKYMEC IT Manager Enabling Remote Code Execution

Tue, 25 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product installed and can receive UDP packets from that system.
Weaknesses CWE-121
References
Metrics cvssV3_0

{'score': 8.5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-25T06:27:20.798Z

Reserved: 2026-08-05T03:02:31.621Z

Link: CVE-2026-68960

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T07:17:10.730

Modified: 2026-08-25T07:17:10.730

Link: CVE-2026-68960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T07:30:12Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow